1

Application Security Engineer Jobs in Florida (NOW HIRING)

Direct the daily execution of the Application Security and Cloud Security functions, balancing near-term delivery, technical quality, and team development. * Establish technical priorities, decision ...

Technical knowledge in security engineering, system and network security, authentication and security protocols, cryptography, and application security. Knowledge of system security vulnerabilities ...

DevSecOps Engineer Location: Miami, Florida (On-Site) 6-month contract Key Responsibilities ... Implement both SaaS-based security testing (SaaST) and dynamic application security testing (DAST ...

AppSec Engineer ID71671

Orlando, FL ยท On-site

$54.75 - $73.25/hr

ABOUT THE ROLE We are looking for a Middle Application Security Engineer to execute hands-on DevSecOps work across CI/CD pipeline security integration, vulnerability management tooling, and automated ...

AppSec Engineer ID71671

Boca Raton, FL ยท On-site

$55.50 - $74.25/hr

ABOUT THE ROLE We are looking for a Middle Application Security Engineer to execute hands-on DevSecOps work across CI/CD pipeline security integration, vulnerability management tooling, and automated ...

AppSec Engineer ID71671

West Palm Beach, FL ยท On-site

$56.75 - $76/hr

ABOUT THE ROLE We are looking for a Middle Application Security Engineer to execute hands-on DevSecOps work across CI/CD pipeline security integration, vulnerability management tooling, and automated ...

AppSec Engineer ID71671

Fort Lauderdale, FL ยท On-site

$56.25 - $75/hr

ABOUT THE ROLE We are looking for a Middle Application Security Engineer to execute hands-on DevSecOps work across CI/CD pipeline security integration, vulnerability management tooling, and automated ...

AppSec Engineer ID71671

Tampa, FL ยท On-site

$55.50 - $74.25/hr

ABOUT THE ROLE We are looking for a Middle Application Security Engineer to execute hands-on DevSecOps work across CI/CD pipeline security integration, vulnerability management tooling, and automated ...

AppSec Engineer ID71671

Jacksonville, FL ยท On-site

$55 - $73.50/hr

ABOUT THE ROLE We are looking for a Middle Application Security Engineer to execute hands-on DevSecOps work across CI/CD pipeline security integration, vulnerability management tooling, and automated ...

AppSec Engineer ID71671

Tallahassee, FL ยท On-site

$55.75 - $74.50/hr

ABOUT THE ROLE We are looking for a Middle Application Security Engineer to execute hands-on DevSecOps work across CI/CD pipeline security integration, vulnerability management tooling, and automated ...

AppSec Engineer ID71671

Miami, FL ยท On-site

$56 - $75/hr

ABOUT THE ROLE We are looking for a Middle Application Security Engineer to execute hands-on DevSecOps work across CI/CD pipeline security integration, vulnerability management tooling, and automated ...

Showing results 41-60

Application Security Engineer information

See Florida salary details

$22

$49

$72

How much do application security engineer jobs pay per hour?

As of Aug 7, 2026, the average hourly pay for application security engineer in Florida is $49.62, according to ZipRecruiter salary data. Most workers in this role earn between $42.21 and $56.39 per hour, depending on experience, location, and employer.

What does an application security engineer do?

An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.

What are some common challenges faced by application security engineers when integrating security into the software development lifecycle?

Application Security Engineers often encounter challenges such as balancing security requirements with development speed, ensuring all team members understand secure coding practices, and keeping up with evolving threats. They frequently work closely with developers, DevOps, and QA teams to embed security controls without disrupting workflows. Overcoming these challenges requires strong communication skills, a deep understanding of both security and software development, and the ability to advocate for security as a shared responsibility across the organization.

What does an application security engineer do?

An Application Security Engineer is responsible for identifying and mitigating security vulnerabilities in software applications throughout their development lifecycle. They work closely with developers to ensure secure coding practices, conduct security assessments and code reviews, and implement tools for threat detection and prevention. Their primary goal is to protect applications from threats such as data breaches, unauthorized access, and other forms of cyber attacks. They also stay updated on the latest security trends and compliance requirements to keep applications safe.

What are the key skills and qualifications needed to thrive as an application security engineer, and why are they important?

To thrive as an Application Security Engineer, you need a solid background in software development, cybersecurity fundamentals, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and relevant certifications like CISSP or CEH is common. Attention to detail, problem-solving abilities, and strong communication skills help you effectively identify risks and collaborate with development teams. These skills are crucial for safeguarding applications against evolving threats and ensuring secure software delivery.

What is the difference between Application Security Engineer vs Security Analyst?

AspectApplication Security EngineerSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentDevelops security measures, reviews code, tests applicationsMonitors security systems, investigates incidents, analyzes threats
Industry UsageTech companies, software firms, organizations with strong app focusBroad sectors including finance, healthcare, government

Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.

What are the most commonly searched types of Application Security Engineer jobs in Florida? The most popular types of Application Security Engineer jobs in Florida are:
What are popular job titles related to Application Security Engineer jobs in Florida? For Application Security Engineer jobs in Florida, the most frequently searched job titles are:
What job categories do people searching Application Security Engineer jobs in Florida look for? The top searched job categories for Application Security Engineer jobs in Florida are:
What cities in Florida are hiring for Application Security Engineer jobs? Cities in Florida with the most Application Security Engineer job openings:
What are popular job titles related to Application Security Engineer jobs in FL? For Application Security Engineer jobs in FL, the most frequently searched job titles are:
Infographic showing various Application Security Engineer job openings in Florida as of August 2026, with employment types broken down into 77% Full Time, 16% Part Time, 1% Temporary, 5% Contract, and 1% Nights. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $103,213 per year, or $49.6 per hour.

Principal InfoSec Engineer Application Security

Philip Morris International

Tampa, FL โ€ข On-site

$160K - $200K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 6 days ago


Job description

Principal InfoSec Engineer Application Security - Tampa, FL
At PMI U.S., we are building a modern nicotine business-focused on helping make a future without cigarettes a reality in America. As the U.S. businesses of Philip Morris International, we are investing in new products, science, and capabilities to provide the approximately 25 million legal age adults who still smoke with better alternatives.
Our approach is rooted in innovation, responsible marketing, and a growing U.S. footprint that spans manufacturing, technology, and commercial operations across the country.
That creates real opportunity. You'll have the space to take ownership, develop new ideas, and contribute to work that is shaping our business and the category. We're looking for people who are curious, collaborative, and motivated by progress-because the scale of what we're building creates room to grow in different directions.
Your 'day to day':
  • Identify cybersecurity gaps in new and existing applications and systems used by the PMI U.S. business unit via a wide variety of methods (e.g., threat modeling, architecture reviews, access model reviews, configuration reviews, static and dynamic application security testing).

  • Take ownership for execution of security assurance for the most critical or complex projects in the PMI U.S. business unit (e.g., a major system implementation or a multi-state rollout). Plan and deliver the security engagement - from initial risk scoping, ongoing design checkpoints, to final pre-go-live assessments. Ensure all security requirements are addressed throughout the project lifecycle, not just at the end.

  • Develop tailored assurance plans for projects in the PMI U.S. business unit that deviate from the standards. For example, if a project is adopting a new technology, determine what additional assessment steps are needed (specialized testing, extra reviews) and deliver them in coordination with other specialized InfoSec teams or external experts.

  • Describe and demonstrate identified issues in various forms (e.g., reports, technical debt definitions) and ensure that relevant stakeholders understand the risk that those vulnerabilities pose to the Company. Advise technology teams on how to replicate identified cybersecurity issues and remediate them in the most effective and cost-efficient way.

  • Coordinate with other Application Security teams to get specialized input as needed. For instance, bring in Offensive Security specialists for targeted ethical hacking activities and integrate their findings into the overall advisory for projects in the PMI U.S. business unit. Also, feedback common project pain points into the AppSec baseline evolution (e.g., if many projects struggle with a certain policy requirement, flag this to potentially clarify or enhance that standard in future).

  • Support creation of global application security strategies and implementation of strategic application security plans and initiatives for PMI U.S

  • Partner with Information Security leaders to ensure that the PMI U.S. business unit follows best practices in the application security domain by continuously optimizing tools, techniques and methodologies.

  • Keep up to date with the constantly evolving cyber threat landscape and the latest developments in technology and cyber risk management.

Key Skills:
  • 10+ years of experience in Information Security, preferably in the IT risk or assurance function (e.g., IT Security, IT Audit, Application Security, Offensive Security) of a large organization or consulting company.

  • Proven track record in autonomously executing complex IT security assessments or IT audits for large scale technology solutions, including technical reviews such as architecture reviews, configuration reviews, automated testing (SAST, DAST).

  • Broad familiarity with various IT domains such as application development, cloud and infrastructure.

  • Understanding of technical depth to challenge design decisions when needed (e.g., questioning why a certain legacy protocol is used, or whether a proposed architecture meets segmentation requirements).

  • Risk evaluation and articulation skills with ability to foresee project constraints and pragmatically suggest risk mitigations that fit within those constraints (balancing ideal security vs. practical delivery).

  • Excellent communication skills (up and down). Ability to lead meetings with project managers and architects to discuss findings and also brief upper management on the residual risks of a project. Strong negotiation skills to ensure necessary security changes are made.

  • Strong report writing skills for executive-level summaries and detailed risk registers. Also adept at improving team processes and refining existing methodologies (e.g., creating a standardized threat model template for all advisors to use).

  • Professional security certifications: CISA (mandatory), CISSP (mandatory), CISM (optional, but preferred)

Annual Base Salary Range: $160,000 - $200,000
What we offer:
  • We offer a competitive base salary, annual bonus (applicable based on level of position), great medical, dental and vision coverage, 401k with a generous company match, incredible wellness benefits, commuter benefits, pet insurance, generous PTO, and much more!
  • We have implemented Smart Work, a hybrid model of working that promotes flexibility in the workplace.
  • Seize the freedom to define your future and ours. We'll empower you to take risks, experiment and explore.
  • Be part of an inclusive, diverse culture where everyone's contribution is respected; Collaborate with some of the world's best people and feel like you belong.
  • Pursue your ambitions and develop your skills with a global business - our staggering size and scale provides endless opportunities to progress.
  • Take pride in delivering our promise to society: To improve the lives of millions of smokers.

PMI is an Equal Opportunity Employer.
PMI is headquartered in Stamford, Conn., and its U.S. affiliates have more than 3,000 employees.
PMI has been an entirely separate company from Altria and Philip Morris USA since 2008. PMI's affiliates first entered the U.S. market following the company's acquisition of Swedish Match in late 2022. Philip Morris International and its U.S. affiliates are working to deliver a smoke-free future. Since 2008, PMI has invested $12.5 billion globally to develop, scientifically substantiate and commercialize innovative smoke-free products for adults who would otherwise continue to smoke with the goal of transitioning legal-age consumers who smoke to better alternatives. In 2022, PMI acquired Swedish Match - a leader in oral nicotine delivery - creating a global smoke-free champion led by the IQOS and ZYN brands. The U.S. Food and Drug Administration has authorized versions of PMI's IQOS electronically heated tobacco devices and Swedish Match's General snus as Modified Risk Tobacco Products and renewal applications for these products are presently pending before the FDA. For more information, please visit www.pmi.com/us and www.pmiscience.com.
#PMIUS
#LI-AC1